Skip to content

Director of Information Security

PlumeRemote (US)September 16, 2026
Remote
Full-time
Security Architecture
Executive

Life at Plume

At Plume, we believe that technology isn't about moving faster, it's about making life’s moments better. Which is why we’ve built the world's first, and only, open and hardware-independent service delivery platform for smart homes, small businesses, enterprises, and beyond. Our SaaS platform uses WiFi, advanced AI, and machine learning to create the future of connected spaces—and human experiences—at massive scale.

We now deliver services to over 60 million locations globally and have managed over 3 billion devices on our platform. We’re expanding rapidly, pioneering a new category, and we achieved our Series F funding in just four years. Our customers include many of the world's largest Internet Service Providers (ISPs) who look to Plume to help them evolve their smart home offerings while gleaning insights from their own data. 

With a bias for action and a love for being trailblazers, the team at Plume embodies a combination of relentless curiosity and imaginative innovation. We challenge ourselves to think in ways that other companies don't, work to do what should be done (rather than what can), and if we can’t do it exceptionally well, we don’t do it. It’s how we've assembled a team of world-class builders, thinkers, and doers. And it’s how we’re reinventing what’s possible every day.

Role Description:

We're looking for a Director of Information Security to lead and mature our security program at a critical inflection point. We've already achieved ISO 27001 and SOC 2 Type 1 certifications — the foundation is in place. Now we need a hands-on leader who can turn that foundation into a durable, well-run program: formalizing policies and procedures, building a high-functioning security team, and protecting our infrastructure, networks, cloud environments, and applications — all without slowing down the engineers and developers who build our products.

This is not a "policy for policy's sake" role. You'll be the person who makes security a natural part of how we build software, not an obstacle to it.

Responsibilities:

Program & Governance

  • Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
  • Author, formalize, and maintain the policies, standards, and procedures required to close any remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor/third-party risk, change management, business continuity, etc.).
  • Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
  • Manage relationships with external auditors, pen testers, and compliance partners.

Security Engineering & Operations

  • Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end.
  • Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response.
  • Establish and continuously improve secure SDLC practices — threat modeling, secure code review, dependency and supply-chain security, CI/CD pipeline security.
  • Own incident response: build the plan, run tabletop exercises, and lead the response when needed.

Team Leadership

  • Lead, coach, and develop security team — establishing clear roles, workflows, and a sense of ownership.
  • Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
  • Define how the team engages with Engineering and Product (embedded reviews, self-service tooling, clear SLAs) to minimize friction and rework.

Cross-Functional Partnership

  • Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership.
  • Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no."
  • Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage.

Qualifications:

  • Bachelor's degree in Information Security, Computer Science, Computer Engineering or related field or equivalent work experience
  • 10+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
  • Direct experience operating within (not just achieving) ISO 27001 and SOC 2 frameworks — you know what "audit-ready" looks like day to day, not just at renewal time.
  • Strong technical depth in cloud security (AWS/GCP), network security, and modern application security (SDLC, AppSec tooling, container/Kubernetes security a plus).
  • Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment.
  • A track record of leading security teams that engineers actually like working with — you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates.
  • Experience managing external auditors, penetration testers, and compliance vendors.
  • Excellent communication skills — able to flex between a whiteboard session with engineers and a risk briefing with the board.

Nice to Have:

  • CISSP, CISM, or similar certification.
  • Experience implementing or operating under ISO 27701 (privacy extension to 27001) and the NIST Cybersecurity Framework (CSF).
  • Experience in a company of similar size/stage (post-certification, scaling team).

How We'll Measure Success (First 3–6 Months):

  • Policies and procedures are fully documented, approved, and operational — not just written for the audit.
  • The team has clear ownership areas, workflows, and is executing proactively rather than reactively.
  • SOC 2 Type 2 audit (or next relevant milestone) is on track with minimal last-minute scrambling.
  • Engineering teams report that security review and tooling add minimal friction to their workflow (measurable via review turnaround time, exception requests, or a simple satisfaction pulse).
  • A functioning incident response process exists and has been tested (tabletop or live).

About Plume

As the creator of the only open, hardware-independent, cloud-controlled experience platform for ISPs and their subscribers, Plume partners with over 400 ISP customers, including some of the world’s largest such as Charter, Liberty Global, and J:COM. 

Using OpenSync, the most widely supported open-source, silicon-to-cloud framework for smart spaces, Plume’s software-defined network allows ISPs to decouple their service offerings from hardware and rapidly curate and deliver new services over a multi-vendor, open-platform architecture.  

Plume is an equal opportunity workplace that maintains a continuing policy of nondiscrimination in all employment practices and decisions, ensuring equal employment opportunities for all qualified individuals without regard to race, color, creed, religion, sex, national origin, age, physical or mental disability, sexual orientation, gender identity, marital status, pregnancy, childbirth or related individual conditions, medical conditions (as defined by state law), military or veteran status, or any other characteristic protected by federal, state or local law.

Job Details

Experience

Executive

Tools & Tech

AWS
GCP
Kubernetes

Preferred Certs

CISM
CISSP